Sergio Lerner, chief scientist and co-founder of RootstockLabs, has called for Bitcoin bridges to adopt mandatory withdrawal delays after nearly 4,000 BTC left the Liquid Network’s federation wallet through an unauthorized peg-out.
Lerner told crypto.news that immediate settlement turns a single validation error into a loss before bridge operators can respond. “Without a time-delay lock, a single validation bug and a total loss become the exact same event, because funds move the moment software says ‘yes,’” he said.
The comments followed an incident in which actors created unbacked L-BTC and used SideSwap’s peg-out service to withdraw nearly 4,000 BTC from the Liquid Federation wallet. Liquid described the actors as purported white-hat hackers, while SideSwap said its service processed the request because the L-BTC appeared valid. The actors later returned 3,400 BTC after Blockstream confirmed that affected bridge nodes had been patched. About 598 BTC remained outstanding, and Liquid resumed block production without restoring transactions or peg operations as of Sep. 10.
Lerner argued that a mandatory delay between the creation of unbacked L-BTC and the release of real BTC could have reduced the damage. Software approval would start a waiting period rather than complete a withdrawal, allowing automated monitoring tools to compare the requested peg-out with BTC backing and flag imbalances before settlement.
Rootstock already enforces a withdrawal delay through its two-way peg. Its PowHSMs wait 4,000 Rootstock blocks, or roughly 36 hours of cumulative proof-of-work, before signing a peg-out. Private keys remain inside the devices, and functionaries cannot instruct the hardware to bypass the waiting period. Lerner said that even a colluding majority of pegnatories cannot steal funds because the HSMs independently verify the block threshold. Compromised functionaries could halt peg operations but could not force an unauthorized early withdrawal.
Lerner also emphasized that revocation controls should be distributed among independent, multi-party functionaries using hardware-enforced rules rather than centralized administrative keys. This would allow temporary pauses while anomalies are reviewed without permitting BTC redirection or confiscation.
The proposal points to native Bitcoin vaults as a longer-term path. Draft Bitcoin proposal BIP-443, which introduces OP_CHECKCONTRACTVERIFY or OP_CCV, could place withdrawal controls in Bitcoin consensus through a soft fork. Lerner said time delays should be tailored to transaction size and risk, with longer periods for large bridge withdrawals and shorter periods for routine payments.